SPIP是一套免费的基于Web的内容发布系统。该系统主要用于在线协作。 SPIP的ecrire/inc/filtres.php脚本中的‘encoder_contexte_ajax’函数存在安全漏洞。远程攻击者可借助特制的序列化对象利用该漏洞实施PHP对象注入攻击,执行任意PHP代码。以下版本受到影响:SPIP 2.1.19之前2.x版本,3.0.22之前3.0.x版本,3.1.1之前3.1.x版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2016-2512 | Django‘django.utils.http.is_safe_url()’安全绕过漏洞 | |
| CVE-2015-8840 | SAP NetWeaver AS Java XML Data Archiving Service服务安全漏洞 | |
| CVE-2016-3980 | SAP NetWeaver AS JAVA Java Startup Framework组件拒绝服务漏洞 | |
| CVE-2016-3979 | SAP NetWeaver AS JAVA Internet Communication Manager组件拒绝服务漏洞 | |
| CVE-2016-3978 | Fortinet FortiOS Web User Interface 安全漏洞 | |
| CVE-2016-3188 | Drupal Prepopulate模块安全漏洞 | |
| CVE-2016-3187 | Drupal Prepopulate模块安全漏洞 | |
| CVE-2016-3153 | SPIP 代码注入漏洞 | |
| CVE-2016-2324 | Git‘path_name()’整数溢出漏洞 | |
| CVE-2016-2315 | Git‘path_name()’安全漏洞 | |
| CVE-2015-6541 | Zimbra Collaboration Server Mail接口跨站请求伪造漏洞 | |
| CVE-2016-3984 | 多款McAfee产品安全漏洞 | |
| CVE-2016-3983 | McAfee Advanced Threat Defense 安全漏洞 | |
| CVE-2016-3963 | Siemens SCALANCE S613 拒绝服务漏洞 | |
| CVE-2016-2513 | Django 安全漏洞 | |
| CVE-2015-5158 | QEMU 基于栈的缓冲区溢出漏洞 | |
| CVE-2016-2381 | Perl 输入验证错误漏洞 | |
| CVE-2016-1375 | Cisco IP Interoperability and Collaboration System 跨站脚本漏洞 | |
| CVE-2016-1180 | LOCKON EC-CUBE Social-button Premium插件跨站脚本漏洞 | |
| CVE-2015-5969 | Novell openSUSE mysql-community-server和mariadb 安全漏洞 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet